BigHugger
sk Skill · mukul975

detecting-dcsync-attack-in-active-directory

Detect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs and flagging non-domain-controller accounts issuing DsGetNCChanges RPC calls. Use when hunting for credential theft via Mimikatz lsadump::dcsync or Impacket secretsdump, investigating lateral movement with domain admin…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
kqlPythonkerberosmimikatzmitre-t1003-006dcsynccredential-theftactive-directoryyamlsplthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python